Vulnerabilities used by  Lockbit3


This information is provided by Ransomware-Vulnerability-Matrix


This is the list of vulnerabilities that have been observed during intrusions by  
Lockbit3

Vendor Product CVE Source
Apache Log4j  🔴  CVE-2021-44228 ("Log4Shell") cisa.gov
Citrix NetScaler ADC & Gateway  🟠  CVE-2023-4966 ("Citrixbleed") doublepulsar.com
Fortinet FortiOS  🔴  CVE-2018-13379 cisa.gov
Fortra GoAnywhere Managed File Transfer  🟠  CVE-2023-0669 cisa.gov
F5 iControl REST  🔴  CVE-2021-22986 cisa.gov
PaperCut PaperCut Application Server CVE-2023–27350 & CVE-2023–27351 twitter.com/MsftSecIntel
Windows NetLogon  🌕  CVE-2020-1472 ("ZeroLogon") cisa.gov
Windows Remote Desktop Services  🔴  CVE-2019-0708 ("BlueKeep") cisa.gov

CVE Severity Levels

Severity Score Range Description
⚪️ Low 0.1 - 3.9 Minor impact on the system; typically does not require immediate action.
🌕 Medium 4.0 - 6.9 Moderate impact; may require action but is generally not urgent.
🟠 High 7.0 - 8.9 Significant impact; needs attention soon to prevent potential exploitation.
🔴 Critical 9.0 - 10.0 Severe impact; requires immediate action due to the high risk of exploitation and potential for serious damage.